Phoenixcontact

Wp 6185-whps Firmware

14 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.05%
  • Published 09.08.2023 07:15:11
  • Last modified 21.11.2024 08:12:20

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.

  • EPSS 0.28%
  • Published 09.08.2023 07:15:11
  • Last modified 21.11.2024 08:12:20

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-...

  • EPSS 0.33%
  • Published 09.08.2023 07:15:11
  • Last modified 21.11.2024 08:12:20

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.

  • EPSS 0.24%
  • Published 09.08.2023 07:15:11
  • Last modified 21.11.2024 08:12:21

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.

  • EPSS 0.07%
  • Published 09.08.2023 07:15:10
  • Last modified 21.11.2024 08:12:19

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.

  • EPSS 0.07%
  • Published 09.08.2023 07:15:10
  • Last modified 21.11.2024 08:12:19

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .

  • EPSS 0.06%
  • Published 09.08.2023 07:15:10
  • Last modified 21.11.2024 08:12:19

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cooki...

  • EPSS 0.03%
  • Published 09.08.2023 07:15:10
  • Last modified 21.11.2024 08:12:20

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.

  • EPSS 0.27%
  • Published 09.08.2023 07:15:10
  • Last modified 21.11.2024 08:12:20

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.

  • EPSS 0.18%
  • Published 09.08.2023 07:15:10
  • Last modified 21.11.2024 08:12:20

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.